Junglewise Threat Intelligence

CVE-2026-60063: AutomationDirect Productivity Suite out-of-bounds write via IOCTL

CVE-2026-60063 · Severity: high · CVSS 7 · Published 2026-07-16

Technologies: AutomationDirect Productivity Suite. Vendors: AutomationDirect.

Executive brief

AutomationDirect Productivity Suite, a software package used to program and manage industrial controllers, contains a vulnerability that could allow a local user to corrupt system memory. If exploited, this could lead to an unauthorized increase in user privileges or cause the entire system to crash, disrupting industrial operations. Organizations should update to version v4.7.0.47 or later to resolve this issue.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in AutomationDirect Productivity Suite versions 4.6.2.2 and prior. The flaw is triggered when the software processes a specially crafted Input/Output Control (IOCTL) request, leading to kernel memory corruption. A local attacker with low privileges can exploit this to achieve privilege escalation or cause a denial-of-service (system instability). The vulnerability is mitigated in version v4.7.0.47.

Affected products

  • AutomationDirect Productivity Suite <=v4.6.2.2

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory
  • 2026-07-16: patched: Patch available in version v4.7.0.47

References

Related threats